Which vulnerabilities could put your business at risk?
Comprehensive penetration testing for every layer
Details
[No details]
Why partner with Bastion for penetration testing
Our customers
Latest advisories
Frequently asked questions
What size or type of organisation do you work with?
Our assurance and advisory services are ideal for mid-sized to large enterprises, government entities, and high-risk sectors needing strategic cybersecurity leadership, governance, and executive-level reporting.
Can we engage Bastion for a one-time consultation?
Yes. While many clients value our ongoing support, we also offer one-time strategy sessions, reviews, or incident readiness assessments.
What industries do you specialise in?
We have deep experience across critical infrastructure, finance, health, government, energy, and regulated industries, but our principles apply across all sectors facing modern cyber risks.
Why does my organization need a penetration test?
Because knowing your weaknesses is the first step to defending them. Pen testing helps uncover hidden risks, meet compliance requirements, and strengthen your overall cybersecurity posture.
Will testing disrupt our operations?
Not at all. We plan carefully to ensure minimal impact on your systems. Tests can be scheduled during low-usage periods or conducted in a staged environment if needed.
How do I book a penetration test or get a quote?
Complete the form on this page and our team will be in touch within one business day to discuss your requirements and provide a scoped proposal.
How long does a penetration test take?
A penetration test typically takes around 5 days, although the exact duration depends heavily on the agreed scope and the specific objectives of the engagement. Penetration testing is tailored to your environment, risk profile and goals, so timelines can vary accordingly.
What's the difference between a vulnerability scan and a penetration test?
A vulnerability scan uses automated tools to identify known weaknesses. A penetration test goes further - our testers simulate real attacker behaviour to validate those risks and uncover more complex issues that tools alone miss.
Do you test cloud environments, web applications and APIs?
Yes. We cover external and internal networks, web and mobile applications, cloud environments, APIs, SaaS platforms and specialist areas including OT/SCADA, wireless and hardware.
How often should we run a penetration test?
Most organisations benefit from annual testing as a baseline, with additional tests following significant changes to systems, applications or infrastructure - or when required for compliance.
Do you offer independent or CREST-certified testing?
Yes. Bastion is a CREST-certified penetration testing provider, meaning our testing meets globally recognised standards for quality, ethics and technical rigour.
Talk to an expert
51 Shortland Street,
Auckland 1010 New Zealand
10 Brandon Street
Wellington 6011 New Zealand
120 Spencer Street
Melbourne 3000 Australia
